Metrics
Affected Vendors & Products
Thu, 21 Aug 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Solidinvoice
Solidinvoice solidinvoice |
|
CPEs | cpe:2.3:a:solidinvoice:solidinvoice:*:*:*:*:*:*:*:* | |
Vendors & Products |
Solidinvoice
Solidinvoice solidinvoice |
Wed, 20 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 19 Aug 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | SolidInvoice Clients clients cross site scripting | |
Weaknesses | CWE-79 CWE-94 |
|
References |
|
|
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-19T22:32:05.818Z
Updated: 2025-08-20T15:16:20.030Z
Reserved: 2025-08-19T13:37:07.795Z
Link: CVE-2025-9171

Updated: 2025-08-20T13:59:33.639Z

Status : Analyzed
Published: 2025-08-19T23:15:27.647
Modified: 2025-08-21T18:27:55.687
Link: CVE-2025-9171

No data.